Design-for-Secure Manufacturing: Why we no longer talk about DfM | Topics

Design-for-Secure-Manufactoring

Design for Manufacturing (DfM) has been standard practice for decades: placeability, testability, test points, pin-bed access — all incorporated early on in the design process to ensure a smooth transition to mass production. What is missing from this list is the question of how cryptographic identities are incorporated into the device. It is precisely this gap that Design-for-Secure-Manufacturing (DfSM) fills.

How DfSM complements DfM

As soon as a device incorporates Secure Boot, a Hardware Security Module (HSM) or a True Random Number Generator (TRNG), the manufacturing process itself becomes part of the security architecture:

  • Key provisioning at the factory — who signs, who writes, who verifies? At which test station? With which audit trail?
  • Use of TRNGs in manufacturing — where is the device’s key material generated, and how does it leave the factory exclusively in a protected form?
  • Secure provisioning of certificates — how does the Public Key Infrastructure (PKI) for the customer fleet reach the device, using which custody model and which verification steps?
  • Boundary scan and in-circuit test (ICT) in relation to tamper protection — test access points required during manufacturing must be securely locked in the field. Lock bits and disable strategies must therefore be incorporated during the design phase.

Why DfSM belongs in the concept phase

Decisions are made early on — in parallel with the system architecture, long before the first pilot batch:

  • Which trust anchor? (Secure element, MCU-internal key storage, external HSM)
  • Which provisioning model? (at the factory, on first boot, during onboarding)
  • Who holds the Root of Trust? (Customer, SYS TEC, joint custodian)

These decisions shape the component selection, the test concept and the test bench configuration in equal measure. If they are made too late, they usually result in redesign cycles — for the HSM model, the test concept, or both.

Cybersecurity is a cross-cutting issue

DfSM is an example of our fundamental approach: cybersecurity is on a par with functional safety and is taken into account at every stage. Threat modelling in the architecture, secure coding in the software, DfSM during series production roll-out. Each of these phases plays a part — and any phase that is omitted will prove more costly to rectify later on.

Get in touch now

Search the website

The internal search function finds pages, documents and blog posts.
Please enter a search term.

What are you looking for?

Frequently searched for:

  • EMC testing
  • Project management
  • Prototype manufacturing
Cookies and Data Protection
Exit the dialogue box and return to the top of the page